The apps—which include Abercrombie & Fitch, Hotels.com, Air Canada, Hollister and Expedia—are using a technology called “session replay” to record customers’ screens without consent. Developed by Glassbox, a customer-experience analytics firm, the tech allows developers to record and play back a screen to monitor user interaction and suss out any errors. (TechCrunch)
Talking point: Though the apps are meant to mask sensitive data, like credit-card information, with black boxes, some unintentionally expose it. For example, the App Analyst, a mobile expert and blogger, found that Air Canada’s iPhone app had been exposing passport numbers and credit-card data in each replay session. That meant Air Canada employees, and anyone else with access to the screenshot database, could see “unencrypted credit card and password information,” as he told TechCrunch. A few weeks prior, Air Canada reported a data breach that had exposed 20,000 profiles.